Trojan

Trojan-PSW.MSIL.Agensla.hnt removal

Malware Removal

The Trojan-PSW.MSIL.Agensla.hnt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.MSIL.Agensla.hnt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-PSW.MSIL.Agensla.hnt?


File Info:

crc32: 2616D47B
md5: 775e403c8fe7560714bb755222f13a4c
name: win.exe
sha1: b5cc605b9388cd1c30945cc12c70b7fe4d275c2c
sha256: c2125e573e71268bfaef4dc9e6e167a51c5ec8f1ed2bd5fbcf8dc163f665a684
sha512: 0c6d55a7026dc15ea444d7ec3404a62952c205500144951211f6794f64a75c1b86dcd4870b902b125affb387c434fa34dd118ecf42086bed51fd2d6c8268b556
ssdeep: 24576:Alb/ll5CvNR8jT/u0dmQykw2vlorFYuucpU8p30X4pU:yKvNeG0dmQ/w2dWFY+U8pkIp
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright 2015 BoxGroup
FileVersion: 9.4.2.3
CompanyName: BoxGroup
LegalTrademarks: Copyright 2015 BoxGroup
Comments: Updegrve Hospitals Mediated Burger Ideal Clamp
ProductName: Proceeding Axle
ProductVersion: 9.4.2.3
FileDescription: Updegrve Hospitals Mediated Burger Ideal Clamp
OriginalFilename: Proceeding Axle.exe
Translation: 0x0409 0x04b0

Trojan-PSW.MSIL.Agensla.hnt also known as:

MicroWorld-eScanTrojan.GenericKD.32794242
FireEyeGeneric.mg.775e403c8fe75607
McAfeeRDN/Generic PWS.y
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderTrojan.GenericKD.32794242
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitTrojan.Generic.D1F46682
TrendMicroPossible_HPGen-38
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-PSW.MSIL.Agensla.hnt
AegisLabTrojan.Multi.Generic.4!c
RisingTrojan.Generic@ML.92 (RDML:FngvgkrVjMIyjxpJO5FYxw)
Endgamemalicious (moderate confidence)
SophosTroj/Steale-FZ
DrWebTrojan.PWS.Siggen2.40361
ZillyaTrojan.Agensla.Win32.780
Invinceaheuristic
McAfee-GW-EditionRDN/Generic PWS.y
FortinetW32/Steale.FZ!tr
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.32794242 (B)
WebrootW32.Trojan.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan[PSW]/MSIL.Agensla
MicrosoftTrojan:Win32/Tiggre!plock
ZoneAlarmTrojan-PSW.MSIL.Agensla.hnt
AhnLab-V3Trojan/Win32.Agent.C3634772
VBA32BScope.TrojanPSW.MSIL.Agensla
ALYacTrojan.GenericKD.32794242
Ad-AwareTrojan.GenericKD.32794242
MalwarebytesSpyware.AgentTesla
PandaTrj/CI.A
ESET-NOD32MSIL/Spy.Agent.AES
TrendMicro-HouseCallPossible_HPGen-38
IkarusTrojan-Ransom.Crypter
GDataTrojan.GenericKD.32794242
AVGWin32:Trojan-gen
Cybereasonmalicious.b9388c
AvastWin32:Trojan-gen
Qihoo-360Win32/Trojan.PSW.737

How to remove Trojan-PSW.MSIL.Agensla.hnt?

Trojan-PSW.MSIL.Agensla.hnt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment